## INTELLIGENCE BRIEFING: 201.3.225.20
Classification: High Risk | Risk Score: 70/100 | Generated: 2026-07-28
EXECUTIVE SUMMARY
IP 201.3.225.20 is classified as a High Risk address exhibiting Tor exit node indicators. The IP operates on ASN 48031 under IPBNB LLC, with geolocation reporting Poland (PL) with coordinates near Stockholm. Despite the subnet (201.3.225.0/24) showing low abuse density (0.1) and 9 clean neighbors, this specific IP demonstrates malicious characteristics including Tor exit node activity and blacklist enumeration.
TECHNICAL PROFILE
Network Attribution:
- ASN: 48031 | Org: IPBNB LLC | Netname: IPbnb-LLC
- CIDR Block: 201.3.225.0/24 | RIR: LACNIC
- Abuse Contact: Available via RDAP
Geolocation:
- Country: Poland (PL) | City: Stockholm (reported)
- Coordinates: 51.92°N, 19.15°E | Timezone: Europe/Warsaw
- Accuracy Radius: 400km | GeoConsensus: True
Service Exposure:
- Open Ports: 22/tcp (SSH), 443/tcp (HTTPS)
- SSH Banner: SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5
- TLS Protocol: TLS 1.3 with cipher suite TLS_AES_256_GCM_SHA384
- DNS PTR: vm23358.bit.hosting (bit.hosting domain)
- TLS Certificate: Self-signed certificate with issuer CN=www.qwkoo6z42ikh.com
THREAT INDICATORS
Primary Indicators:
- Tor Exit Node Indicators: Observed (abuseConfidenceScore present)
- Blacklist Status: Listed on 1 blacklist source
- DNSBL Enumeration: Listed on 1 of 8 total DNSBL lists
- Known Attacker Status: Not flagged as known attacker
- Spam Source: Not flagged
Risk Assessment:
- Reputation: High Risk
- Provider Score: 0 | Authority Score: 0
- Stability Label: Unassigned
- Control Plane: BGP prefix 201.3.225.0/24 with origin ASN 48031
- Route Stability: False (non-stable routing)
OBSERVATION HISTORY
Recent Activity (July 28, 2026):
- Connection failures observed on HTTPS (confidence: 30%)
- TLS certificate inspection with TLS 1.3 handshake (confidence: 90%)
- SSH service banner captured (confidence: 90%)
- Subnet abuse classification: "mostly_clean" (confidence: 75%)
- Geolocation inference: Poland with 52% confidence (confidence: 52%)
Temporal Analysis:
- Threat Persistence Days: 0
- Threat Observation Count: 1
- Persistence Classification: Not persistently malicious
- Ownership Changes: 0
- Average Ownership Duration: Not established
NETWORK NEIGHBORHOOD ANALYSIS
Subnet Profile: 201.3.225.0/24
- Total Siblings: 10 | Active Siblings: 0
- Abuse Density: 0.1 (low)
- Threat Siblings: 1 | Inherited Risk: 2
- Classification: Mostly Clean
Neighbor Risk Distribution:
- High Risk: 0 | Medium Risk: 0 | Low Risk: 9
- All Neighbors: Risk Score 0, Authority Score 50
- Assessment: This IP is an outlier within an otherwise clean subnet
RELATIONSHIP MAPPING
Network Relationships:
- Same Network: IPBNB-LLC (multiple entries)
- DNS Associations: vm23358.bit.hosting (4 DNS link entries)
RECOMMENDED ACTIONS
Based on the high risk profile and Tor exit node indicators, the following defensive measures are recommended:
Firewall/Network Rules:
- Block inbound connections to ports 22 (SSH) and 443 (HTTPS) from this IP
- Consider blocking outbound connections to this IP if it represents a threat actor
- Implement rate limiting to prevent connection flooding
Threat Intelligence Integration:
- Add to threat intelligence watchlist
- Monitor for certificate changes on associated domain vm23358.bit.hosting
- Track subnet 201.3.225.0/24 for additional malicious activity
Monitoring:
- Alert on connection attempts from this IP
- Monitor for changes in DNS resolution
- Track blacklist status changes
ASSESSMENT CONCLUSION
IP 201.3.225.20 warrants defensive blocking due to Tor exit node indicators and high risk classification. While the broader subnet demonstrates low abuse density, this specific IP's behavior aligns with anonymization infrastructure typically exploited for malicious purposes. The inconsistency between the IP's high risk profile and its clean neighborhood suggests it may be a compromised or repurposed host within otherwise benign infrastructure. Immediate blocking is recommended, with ongoing monitoring for related activity on associated domains and subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPBNB Abuse Contact |
| ASN | AS48031 |
| Network Name | IPbnb-LLC |
| CIDR Block | 201.3.225.0/24 |
| RIR | LACNIC |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm23358.bit.hosting |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm23358.bit.hosting |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 59% | 2 | 18 |
| routing | 34% | 3 | 4 |
| services | 37% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 37% | 13 | 35 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 18:17:54 UTC |
| Last Seen | 2026-08-12 01:41:48 UTC |
| Profile Built | 2026-08-12 02:45:44 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 70 |
Full dossier details are available via our API.